Microsoft 365 Scam and Kali365 Toolkit Hack Home Categories Hijackers Microsoft 365 Scam and Kali365 Toolkit Hack 0 0 11 1 1mo ago 2026-06-16T16:19:53-05:00 1mo ago 2026-06-16T16:30:23-05:00 Online Threat Alerts The Federal Bureau of Investigation (FBI) has issued an urgent warning regarding a widespread Microsoft 365 phishing scam driven by a malicious hacking toolkit called "Kali365". This dangerous scam relies on tricking users into entering an authorization code on a real Microsoft webpage. This action allows hackers to completely bypass passwords and multi-factor authentication (MFA) to hijack Outlook, Teams, and OneDrive accounts. How the Kali365 Scam WorksThe Phishing Email: You receive an urgent email that mimics a standard document-sharing service like SharePoint or OneDrive.The Real Website, Fake Code: The message instructs you to go to a legitimate, real Microsoft website and enter a specific "device code" provided in the email.The Trap: Because the website is a real Microsoft page, users think it is safe. However, typing that code approves a login request for the hacker's device.Token Theft: The automated tool steals your login token. The scammer gains permanent access to your emails and files without ever knowing your password.Other Common Microsoft 365 ScamsFake Renewal Bills: Emails claiming your Microsoft 365 subscription expired. They ask for credit card numbers on fake payment pages.Storage Full Alerts: Messages warning that your OneDrive is 100% full. They threaten to delete your files if you do not click their link.Tech Support Pop-ups: Scary browser pop-ups with a phone number. They claim your computer is locked or has a virus.Signs of a ScamAn unexpected request to enter a login or device code.High urgency language demanding immediate action.Links pointing to strange domains like "office365family.com" instead of the official microsoft.com.Demands for money or credit card updates through attached files.How to Protect YourselfNever enter a device code that you did not personally request.Check your Microsoft account security page regularly to review active login sessions and unfamiliar devices.Avoid clicking links inside unexpected billing or document notifications.Forward suspicious emails as attachments to the official Microsoft phishing team at phish@office365.microsoft.com.Report any scam attempts or losses directly to the FBI's Internet Crime Complaint Center (IC3). Check the comment section below for answers or additional information. Share what you know, or ask a question about this article by leaving a comment below. Online Threat Alerts is not affiliated with or endorsed by any trademark owner mentioned in this article. Some of the information in samples in this article may have been impersonated or spoofed. Save + Was this article helpful? (1) (0) More For You Why Cybersecurity Software Requires Professional Translations WordPress Security Mistakes Small Business Owners Make Ropes and Gray Scam - How to Protect Yourself NAOBL Scam Text, Emails and Call - How to Protect Yourself 672 Area Code Scam Texts and Calls - How to Protect Yourself Social Security Weaad 2026 Scam Prevention - How to Protect Yourself Is Best Mama Kitchen Email a Scam or is it Legitimate? Dawn Dish Soap Scam - How to Protect Yourself 8504981002 AT&T Unauthorized Transaction Call Scam Text About USPS Delivery Scam: Beware Is Gogodior an Untrustworthy Online Store? limerencexs.com is an Untrustworthy Online Store? Vogue at fabsviews.com - it is a Fraudulent Website 'Microsoft Updates to Our Terms of Use and Privacy Statement' Phishing Scam Comments / Answers Remove sensitive information from your post. Your IP address will be used to display your estimated location. Enter comment post here